Beneath the Mask: Can Contribution Data Unveil Malicious Personas in Open-Source Projects?
In February 2024, after building trust over two years with project maintainers by making a significant volume of legitimate contributions, GitHub user "JiaT75" self-merged a version of the XZ Utils project containing a highly sophisticated well-disguised backdoor targeting sshd processes running on systems with the backdoored package installed.
sans-beneath-mask-ruby-nealon (PDF, 1.18MB)
13 May 2025Related Content
The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection
Research PaperThis paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.
- 11 Aug 2026
- Garo Sinanian
Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making
Research PaperSecurity leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.
- 11 Aug 2026
- Arcadio Aguilar
Reconstructing Deleted File Activity Using FSEvents from macOS
Research PaperThis paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.
- 30 Jul 2026
- Josh Clevenger
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
Research PaperModern Security Operations Centers (SOCs) face a deepening burnout crisis.
- 20 Jul 2026
- Jose "Ricky" Banda
Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks
Research PaperThis study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.
- 22 Jun 2026
- Eric Fletcher
Capturing the Click: Process-Based Detection of Malicious Link Interactions
Research PaperThis research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.
- 22 Jun 2026
- Daniel Gott
From Alert to Evidence: Evaluating AI Agents for Cyber Forensic Triage
Research PaperCyber defense teams are beginning to experiment with large language models in security operations, but their usefulness in digital forensics and incident triage is still uncertain.
- 11 Jun 2026
- Connor Blackard
Know Your Blind Spots: Better Visibility Through EDR Policy Hardening
Research PaperEndpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.
- 9 Jun 2026
- Joshuah Williams
Secure By Design: An Exploration of the Application of Generative AI in Threat Modeling Technical Design Documents
Research PaperThis paper explores the efficacy of large language models (LLMs) for creating comprehensive threat models by analyzing technical design documents, particularly when provided with additional contextual information about the product's underlying infrastructure and deployment environment.
- 27 May 2026
- Mark Oswald
Leveraging Large Language Models for Cross-Vendor Firewall Configuration Migration: A Comparative Case Study of Claude and ChatGPT
Research PaperThis paper investigates how two current-generation large language models (LLMs) perform on a single, representative firewall migration task.
- 12 May 2026
- Omar Zaman
Applying CIS Controls to AI Workflows
Research PaperThis research provides guidance on using the CIS Controls in conjunction with AI-specific frameworks to build a robust information security program.
- 12 May 2026
- Brian Ventura
Autonomous Defense Induced Disruption: How AI-Driven Automated Response Can Be Manipulated to Disrupt Enterprise Operations
Research PaperThe research highlights the need for governance controls, privilege-aware safeguards, and system-level constraints to prevent autonomous containment from causing operational disruption.
- 12 May 2026
- Marcio Enriquez
Your Sensitive Data Has Left the Chat: LLMs as Sensitive Data Detectors
Research PaperThis paper seeks to evaluate the hypothesis that language models, large and small, can perform well at sensitive data classification and to offer a solution for companies trying to detect contextually sensitive data in their AI workflows.
- 12 May 2026
- Colten Davis
A Forensic Study of Artifact Persistence in Containerd-Based Kubernetes Workloads
Research PaperA container is a standard unit of software that packages code, including its dependencies, so the application runs quickly and reliably across computing environments.
- 12 May 2026
- Ahmed Alharbi
Implementing Micro-Segmentation in a Legacy Enterprise Lab Network: A Zero Trust Approach to Reducing Lateral Movement, Improving Containment, and Controlling Operational Overhead
Research PaperThis study evaluates micro-segmentation as a practical Zero Trust control in a Windows Active Directory lab that models common legacy dependencies (directory services, file services, a web tier, and a database tier).
- 24 Mar 2026
- Dennis Ankrah
Assessing the Impact of Memory Acquisition on Key Windows Artifacts
Research PaperThis research evaluates the impact of memory capture tools on data at rest, aiming to understand the degree of change that occurs to artifacts, measure differences based on tool selection, and inform best practices for live responders.
- 20 Mar 2026
- Russell Devine
Leveraging Generative AI for Password Cracking Efficiency Under Resource Constraints
Research PaperThe purpose of this research is to investigate whether generative AI can alleviate the hardware and financial burdens of password cracking (password recovery) while maintaining or even improving cracking success rates.
- 20 Mar 2026
- Wesley Keller
Detecting AI Pickling
Research PaperThis study examines whether static analysis is a dependable "certification gate" for ingesting third-party, pickle-based AI model artifacts from open-source model hubs into a trusted internal registry.
- 12 Mar 2026
- Bryan Nice
How Many LLMs Does it Take to Classify a Suspicious Email?
Research PaperThis study examines the accuracy, reliability, and operational behavior of three widely available LLMs using a dataset of 2000 human-written emails containing both legitimate and suspicious messages.
- 12 Mar 2026
- Bridget Bartell
Autonomous Threat Emulation and Detection Using Agentic AI
Research PaperTraditional threat emulation frameworks struggle to capture the dynamic and adaptive behaviours of modern Advanced Persistent Threats (APTs), leaving defenders reliant on static tests that quickly become obsolete.
- 10 Mar 2026
- Marcus Dillion Yin
